VendorsAlstrasofttemplate_sellerall versions
Vulnerabilities

Alstrasoft Template Seller

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2007-2776
AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject a credential variable setting and obtain administrative access via a direct request to admin/changeinfo.php.
Published 2007-05-21 · Modified
10.01 PoCEPSS 0.086
CVE-2007-2777
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.
Published 2007-05-21 · Modified
7.51 PoCEPSS 0.063
CVE-2005-3797
PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary PHP code via the config[basepath] parameter.
Published 2005-11-24 · Modified
7.51 PoCEPSS 0.038
CVE-2006-4591
Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow remote attackers to execute arbitrary PHP code via a URL in the config[template_path] parameter to (1) payment/payment_result.php or (2) /payment/spuser_result.php.
Published 2006-09-06 · Modified
7.51 PoCEPSS 0.025
CVE-2005-3798
SQL injection vulnerability in admin/index.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary SQL commands via the username field.
Published 2005-11-24 · Modified
7.5EPSS 0.014
CVE-2006-0222
Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to inject arbitrary web script or HTML via the tempid parameter.
Published 2006-01-16 · Modified
4.31 PoCEPSS 0.017